package jdbc;

import java.sql.*;

public class JDBCDemo7 {
    public static void main(String[] args) {
        UserInfo userInfo = InputUtil.getInputObject(new UserInfo(),"欢迎登录","登录");
        try (Connection con = DBUtil.getConnection()) {
            Statement stmt = con.createStatement();
            // 使用PreparedStatement  预编译SQL语句  值的位置用 ? 占位
            String sql = "SELECT id,password,username,nickname,age "+
                    "FROM userinfo "+
                    "WHERE username = ? AND password = ?";
            PreparedStatement ps = con.prepareStatement(sql);
            ps.setString(1,userInfo.getUsername());//第一个 ? 的位置 设置为 userInfo.getUsername()
            ps.setString(2,userInfo.getPassword());
            ResultSet rs = ps.executeQuery();
            if (rs.next()){
                System.out.println("登录成功");
            }else {
                System.out.println("登录失败，用户名或密码错误");
            }

        }catch (SQLException e){
            e.printStackTrace();
        }
    }
}
